Home / Security & Trust

Security & trust

Security and resiliency aren't features. They're required.

Public agencies hold residents' data and process real money. RecreationHQ is built, from the architecture up, to meet that responsibility, so your IT reviewer and your finance office can both say yes.

Isolated & encrypted by tenant

Every organization runs on separate infrastructure with its own dedicated encryption key, aligned to StateRAMP Moderate requirements. Your data is never commingled.

PCI-compliant payments

Payment processing runs through a PCI-compliant provider. We never store full card numbers, and every transaction is traceable to the same ledger as registration.

Automatic disaster recovery

Your data is replicated to a second AWS region for automatic recovery. Backup and restore are included for every customer, at no extra charge, on every plan.

Role-based access & SSO

Granular roles and permissions keep staff in their lane, with SSO (SAML/OIDC) and domain controls available for larger agencies and enterprise.

Serverless, scales on its own

The platform scales up and down automatically, so registration morning, your single busiest hour, runs as smoothly as any other day.

Open, and never locked in

An open API and a custom domain you set up in a few clicks mean RecreationHQ fits your existing systems. Transparency beats lock-in, your data is always yours to export.

StateRAMP ModeratePCI-compliant paymentsAWS multi-regionEncrypted in transit & at restSSO · SAML / OIDCOpen API

Detailed security documentation and a compliance summary are available to agencies under evaluation. Contact security@recreationhq.net.

Built for the people who can say no

Bring your IT reviewer. We'll pass.

Start with a free cost-recovery audit, and we'll include the security and compliance summary your procurement team needs.

Get my free cost-recovery audit →